Your OTP isn't a One-Time-Password any more. And that carries a security cost
Every time you book a ride, your driver asks you for an “OTP”. Increasingly, that OTP is no longer a one-time password.
A quiet substitution has spread through India’s ride-hailing apps. Rapido and Namma Yatri took the OTP, the four-digit number a passenger reads to their driver, and turned it into a standing PIN: One fixed value tied to the account, repeated on every trip. Uber has since adopted the same model in India while keeping a fresh per-ride code in the United States. The question worth asking is: What can a genuine one-time password do that a fixed PIN cannot?
Start with what each instrument is actually for, because they answer different questions. A PIN authenticates a person; it says that whoever offers it knows a secret belonging to the account. A one-time password authenticates an event; it says that this specific booking, made moments ago, is the one this driver is about to begin. That distinction carries real weight, and three properties follow from it that no fixed number can reproduce.
The first is scope. An OTP is valid for a single booking, and only while it is live, so the same value is never correct twice. A PIN is correct for every ride an account will ever take, so it carries no information about which ride is which. It cannot tell apart the trip you booked from a trip booked in your name by someone else, because both produce the........
